[Owasp-leaders] OWASP Top 10 Methodology

Dennis Groves dennis.groves at owasp.org
Tue Mar 5 19:16:38 UTC 2013

On 5 Mar 2013, at 19:06, Paweł Krawczyk wrote:

> But companies have been doing that for years.

No they haven't. You are confusing correlation and causation.

We stock bananas in the store and people sure enough purchase them; we 
know how many to purchase based on statistics - last years sales etc… 
that is we can predict how quickly banana's disappear from the shelves 
with some degree of accuracy.

We are only starting to be able to correlate that some groups of 
individuals are more likely to purchase bananas based on prior purchase 
histories and the like. Sometimes we can correlate that people who 
purchase strawberries are more likely to purchase bananas.

But we have never been able to predict if any **specific individual** 
will purchase the banana.


[Dennis Groves](http://about.me/dennis.groves), MSc
[Email me](mailto:dennis.groves at owasp.org) or [schedule a 

*This email is licensed under a [CC BY-ND 
3.0](http://creativecommons.org/licenses/by-nd/3.0/deed.en_GB) license.*

**Please do not send me Microsoft Office/Apple iWork documents.**
Send [OpenDocument](http://fsf.org/campaigns/opendocument/) instead!
Stand up for your freedom to install [free 

> The idea that some lives matter less is the root of all that’s wrong 
> with the world. -- Paul Farmer

More information about the OWASP-Leaders mailing list